← Previous day

Next day →
Day in brief

Microsoft Entra Domain Services TLS 1.2 migration is the day’s main operational signal; other updates clarify federation, custom domains, and forest trusts.

The 1 July record is a documentation-update day: all nine supplied entries are Microsoft Learn updates, with no new or removed items and no Message Center announcements. The clearest operational change is security guidance for disabling TLS 1.0 and 1.1 in Microsoft Entra Domain Services; the remaining notable updates clarify configuration, permissions, or existing documentation rather than announce new features, previews, or general availability.

  • This is security guidance for an announced protocol change, not a feature launch. Microsoft describes disabling TLS 1.0 and 1.1 and moving to TLS 1.2 or later, citing stronger cipher suites, perfect forward secrecy, and compliance benefits. Administrators should review Domain Services integrations for legacy TLS dependencies, but no new enforcement date is supplied.

  • The updated Workload ID guidance explains that the issuer and subject in a federated identity credential are matched against the corresponding claims in the managed identity token. Microsoft identity platform issues an app access token to the external workload only after that validation succeeds. This is a configuration and behavior clarification, not evidence of a newly introduced capability.

  • The updated instruction says users must sign in to the Microsoft Entra admin center as at least a Domain Name Administrator. The evidence supports a permissions/documentation clarification, not a change to role definitions or RBAC behavior; administrators should use that role check when delegating custom URL domain work.

  • Microsoft updated the Entra ID pages for forest-trust concepts, PowerShell creation, and the forest-trust tutorial. The supplied summaries identify the affected documentation but do not describe a new feature, changed prerequisite, or changed forest-trust behavior, so this should be treated as documentation maintenance.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

9 updates

3

Howto Use Recommendations

Updated

Most recommendations follow the same pattern. You're provided information about how the recommendation works, its value, and some action steps to address the recommendation. This section provides an overview of the details provided in a recommendation, but aren't specific to one recommendation.

3
1

How to migrate to Transport Layer Security (TLS) 1.2 enforcement for Microsoft Entra Domain Services

Updated

Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions is not known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.

1

Custom Url Domain

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Domain Name Administrator](~/identity/role-based-access-control/permissions-reference.md#domain-name-administrator).

1

Workload Identity Federation Config App Trust Managed Identity

Updated

- *issuer*, *subject* are the key pieces of information needed to set up the trust relationship. When the Azure workload requests Microsoft identity platform to exchange the managed identity token for an Entra app access token, the *issuer* and *subject* values of the federated identity credential are checked against the `issuer` and `subject` claims provided in the Managed Identity token. If that validation check passes, Microsoft identity platform issues an access token to the external software workload.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…